From b1a9a4e54e26aa36d1ec7e63a8f5a0952c55fbb4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 15 Oct 2024 23:34:27 +0000 Subject: [PATCH] Publish Advisories GHSA-5mh9-r3rr-9597 GHSA-9qcf-c26r-x5rf GHSA-vqcx-jw4r-6fp3 GHSA-698c-2x4j-g9gq GHSA-fjwp-r6fm-q6qw GHSA-3h57-hmj3-gj3p GHSA-9vfc-qxc8-wrpq --- .../05/GHSA-5mh9-r3rr-9597/GHSA-5mh9-r3rr-9597.json | 5 +++-- .../07/GHSA-9qcf-c26r-x5rf/GHSA-9qcf-c26r-x5rf.json | 2 +- .../03/GHSA-vqcx-jw4r-6fp3/GHSA-vqcx-jw4r-6fp3.json | 4 ++-- .../05/GHSA-698c-2x4j-g9gq/GHSA-698c-2x4j-g9gq.json | 13 +++++++++++-- .../05/GHSA-fjwp-r6fm-q6qw/GHSA-fjwp-r6fm-q6qw.json | 6 +++++- .../03/GHSA-3h57-hmj3-gj3p/GHSA-3h57-hmj3-gj3p.json | 2 +- .../11/GHSA-9vfc-qxc8-wrpq/GHSA-9vfc-qxc8-wrpq.json | 2 +- 7 files changed, 24 insertions(+), 10 deletions(-) diff --git a/advisories/github-reviewed/2020/05/GHSA-5mh9-r3rr-9597/GHSA-5mh9-r3rr-9597.json b/advisories/github-reviewed/2020/05/GHSA-5mh9-r3rr-9597/GHSA-5mh9-r3rr-9597.json index d0c6f7487ee..03d87c362c0 100644 --- a/advisories/github-reviewed/2020/05/GHSA-5mh9-r3rr-9597/GHSA-5mh9-r3rr-9597.json +++ b/advisories/github-reviewed/2020/05/GHSA-5mh9-r3rr-9597/GHSA-5mh9-r3rr-9597.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mh9-r3rr-9597", - "modified": "2023-12-07T23:05:12Z", + "modified": "2024-10-15T23:33:01Z", "published": "2020-05-21T21:08:33Z", "aliases": [ "CVE-2020-5529" @@ -75,7 +75,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-665" + "CWE-665", + "CWE-94" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2020/07/GHSA-9qcf-c26r-x5rf/GHSA-9qcf-c26r-x5rf.json b/advisories/github-reviewed/2020/07/GHSA-9qcf-c26r-x5rf/GHSA-9qcf-c26r-x5rf.json index dfb4116ead8..cff7d3b526d 100644 --- a/advisories/github-reviewed/2020/07/GHSA-9qcf-c26r-x5rf/GHSA-9qcf-c26r-x5rf.json +++ b/advisories/github-reviewed/2020/07/GHSA-9qcf-c26r-x5rf/GHSA-9qcf-c26r-x5rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qcf-c26r-x5rf", - "modified": "2021-10-21T21:18:39Z", + "modified": "2024-10-15T23:33:04Z", "published": "2020-07-01T17:55:03Z", "aliases": [ "CVE-2019-13990" diff --git a/advisories/github-reviewed/2022/03/GHSA-vqcx-jw4r-6fp3/GHSA-vqcx-jw4r-6fp3.json b/advisories/github-reviewed/2022/03/GHSA-vqcx-jw4r-6fp3/GHSA-vqcx-jw4r-6fp3.json index a384b3c2f48..46c020be74a 100644 --- a/advisories/github-reviewed/2022/03/GHSA-vqcx-jw4r-6fp3/GHSA-vqcx-jw4r-6fp3.json +++ b/advisories/github-reviewed/2022/03/GHSA-vqcx-jw4r-6fp3/GHSA-vqcx-jw4r-6fp3.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-vqcx-jw4r-6fp3", - "modified": "2023-10-27T17:14:51Z", + "modified": "2024-10-15T23:33:27Z", "published": "2022-03-30T00:00:25Z", "aliases": [ "CVE-2022-28136" ], "summary": "CSRF vulnerability and missing permission check in Jenkins JiraTestResultReporter Plugin", - "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.", + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin version 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2022/05/GHSA-698c-2x4j-g9gq/GHSA-698c-2x4j-g9gq.json b/advisories/github-reviewed/2022/05/GHSA-698c-2x4j-g9gq/GHSA-698c-2x4j-g9gq.json index 9dadac468a0..e3b0087f228 100644 --- a/advisories/github-reviewed/2022/05/GHSA-698c-2x4j-g9gq/GHSA-698c-2x4j-g9gq.json +++ b/advisories/github-reviewed/2022/05/GHSA-698c-2x4j-g9gq/GHSA-698c-2x4j-g9gq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-698c-2x4j-g9gq", - "modified": "2024-02-22T20:26:58Z", + "modified": "2024-10-15T23:33:07Z", "published": "2022-05-14T01:10:16Z", "aliases": [ "CVE-2016-6817" @@ -125,11 +125,20 @@ { "type": "PACKAGE", "url": "https://github.com/apache/tomcat" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/94462" + }, + { + "type": "WEB", + "url": "http://www.securitytracker.com/id/1037330" } ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-835" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2022/05/GHSA-fjwp-r6fm-q6qw/GHSA-fjwp-r6fm-q6qw.json b/advisories/github-reviewed/2022/05/GHSA-fjwp-r6fm-q6qw/GHSA-fjwp-r6fm-q6qw.json index 63d37aa9854..6c86b70206b 100644 --- a/advisories/github-reviewed/2022/05/GHSA-fjwp-r6fm-q6qw/GHSA-fjwp-r6fm-q6qw.json +++ b/advisories/github-reviewed/2022/05/GHSA-fjwp-r6fm-q6qw/GHSA-fjwp-r6fm-q6qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fjwp-r6fm-q6qw", - "modified": "2024-02-22T21:32:30Z", + "modified": "2024-10-15T23:33:05Z", "published": "2022-05-14T01:10:15Z", "aliases": [ "CVE-2016-8747" @@ -148,6 +148,10 @@ { "type": "WEB", "url": "http://tomcat.apache.org/security-9.html" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/96895" } ], "database_specific": { diff --git a/advisories/github-reviewed/2023/03/GHSA-3h57-hmj3-gj3p/GHSA-3h57-hmj3-gj3p.json b/advisories/github-reviewed/2023/03/GHSA-3h57-hmj3-gj3p/GHSA-3h57-hmj3-gj3p.json index 6df3f417818..339ffb1c72d 100644 --- a/advisories/github-reviewed/2023/03/GHSA-3h57-hmj3-gj3p/GHSA-3h57-hmj3-gj3p.json +++ b/advisories/github-reviewed/2023/03/GHSA-3h57-hmj3-gj3p/GHSA-3h57-hmj3-gj3p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h57-hmj3-gj3p", - "modified": "2023-03-16T21:38:54Z", + "modified": "2024-10-15T23:33:31Z", "published": "2023-03-08T17:20:04Z", "aliases": [ "CVE-2023-27530" diff --git a/advisories/github-reviewed/2023/11/GHSA-9vfc-qxc8-wrpq/GHSA-9vfc-qxc8-wrpq.json b/advisories/github-reviewed/2023/11/GHSA-9vfc-qxc8-wrpq/GHSA-9vfc-qxc8-wrpq.json index 644427ba39a..dfc845ea7e9 100644 --- a/advisories/github-reviewed/2023/11/GHSA-9vfc-qxc8-wrpq/GHSA-9vfc-qxc8-wrpq.json +++ b/advisories/github-reviewed/2023/11/GHSA-9vfc-qxc8-wrpq/GHSA-9vfc-qxc8-wrpq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vfc-qxc8-wrpq", - "modified": "2023-12-05T21:56:53Z", + "modified": "2024-10-15T23:34:03Z", "published": "2023-11-28T18:30:23Z", "aliases": [ "CVE-2023-48848"